CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) — Threadlinqs Intelligence
As of 2026-07-16, CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) is a critical-severity vulnerability threat attributed to Storm-2603 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1378 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-16 · revalidated 1× · latest source
Attribution: Storm-2603 · China · FINANCIAL
CISA issued an advisory on July 14, 2026 warning that three on-premises Microsoft SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) are under active exploitation, with
On July 14, 2026, CISA published an advisory urging administrators to harden on-premises Microsoft SharePoint Server deployments after confirming active, in-the-wild exploitation of three vulnerabilities: CVE-2026-32201 (CVSS 6.5, spoofing via improper input validation enabling unauthenticated reflected XSS/impersonation, disclosed March 2026 and added to CISA's KEV catalog on 2026-04-14), CVE-2026-45659 (CVSS 8.8, remote code execution via deserialization of untrusted data, requiring only Site Member-level authentication, patched May 2026 and added to KEV on 2026-07-01 despite Microsoft's initial 'exploitation less likely' rating), and CVE-2026-56164 (CVSS 5.3, elevation of privilege via missing authentication for a critical function, shipped in July 2026 Patch Tuesday and added to KEV the same day it was disclosed, 2026-07-14).
All three affect every supported on-premises SharePoint Server edition (Subscription Edition, 2019, and 2016/Enterprise Server 2016); SharePoint Online/Microsoft 365 is not affected. Post-exploitation activity observed by CISA and Microsoft involves theft of IIS/ASP.NET machine keys and abuse of .NET deserialization to forge authentication tokens, maintain persistence across patch cycles, and deploy malware. This tradecraft mirrors the July 2025 'ToolShell' SharePoint campaign (CVE-2025-49704/49706/53770/53771), in which the China-based actor Storm-2603 (aka Warlock Group / GOLD SALEM), along with Linen Typhoon and Violet Typhoon, exploited on-prem SharePoint to drop the spinstall0.aspx web shell, exfiltrate ASP.NET machine keys via a crafted GET request, establish persistence through scheduled tasks and Group Policy Object modification, and ultimately deploy Warlock ransomware via DLL search-order hijacking. Storm-2603 has continued targeting on-prem SharePoint with the same machine-key-theft objective roughly a year later, reusing the tactic against the newly disclosed 2026 CVEs.
Two further July 2026 Patch Tuesday SharePoint flaws are not yet confirmed exploited but carry Microsoft's 'Exploitation More Likely' designation and CISA flagged them as high-priority: CVE-2026-55040 (CVSS 9.1, critical security-feature bypass; the first half of a two-bug chain whose second, still-embargoed component is expected to complete an unauthenticated RCE chain in August 2026) and CVE-2026-58644 (CVSS 9.8, critical unauthenticated network RCE). Shadowserver telemetry cited in coverage counted roughly 10,000 internet-exposed on-prem SharePoint instances, with over 800 still unpatched against CVE-2026-32201 and CVE-2026-45659 as of the advisory date. CISA's Binding Operational Directive timeline required FCEB agencies to remediate CVE-2026-45659 by 2026-07-04 and the newly added CVE-2026-56164/CVE-2026-32201 exploitation by 2026-07-17. Recommended mitigations include immediate patching, enabling AMSI integration for SharePoint (to catch malicious POST requests), deploying Microsoft Defender AV, placing a Layer 7 reverse proxy in front of SharePoint, restricting external access to SharePoint Central Administration, rotating ASP.NET machine keys after patching, and enhanced logging for anomalous IIS/w3wp.exe activity.
Weaknesses (CWE)
CWE-290, CWE-79, CWE-502, CWE-306, CWE-288, CWE-20, CWE-1390
Target sectors: government administration, finance, health, education, technology, manufacturing, critical infrastructure, energy
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-55040, CVE-2026-58644, T1590, T1595, T1588, T1190, T1059, T1059, T1203, T1505, T1053, T1078